Improper Check for Certificate Revocation in cURL - CVE-2020-8286
Published: December 9, 2020 / Updated: October 28, 2023
Vulnerability identifier: #VU48895
CSH Severity: Medium
CVSS v4 BT: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-8286
CWE-ID: CWE-299
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrectly implemented checks for OCSP stapling. A remote attacker can provide a fraudulent OCSP response that would appear fine, instead of the real one.
Affected software
cURL
Cloud Pak for Security (CP4S)
Gentoo Linux
ClevOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
macOS
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
Slackware Linux
Junos OS
Ubuntu
openEuler
Junos OS Evolved
Fedora
curl (Alpine package)
jbcs-httpd24 (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-jansson (Red Hat package)
curl (Red Hat package)
curl (Debian package)
jbcs-httpd24-curl (Red Hat package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-brotli (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
curl (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl3 (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl4 (Ubuntu package)
curl
curl-debuginfo
curl-debugsource
libcurl4-32bit
libcurl4
libcurl4-debuginfo-32bit
libcurl4-debuginfo
libcurl-devel
libcurl
curl-help
TensorFlow
Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
OpenShift Virtualization
Red Hat OpenShift Jaeger
Splunk Universal Forwarder
Splunk Enterprise
PeopleSoft Enterprise PeopleTools
Oracle Communications Billing and Revenue Management
GitLab Enterprise Edition
Gitlab Community Edition
BIG-IP PEM
BIG-IP FPS
BIG-IP LTM
BIG-IP AFM
BIG-IP Analytics
BIG-IP ASM
BIG-IP APM
BIG-IP GTM
BIG-IP DNS
BIG-IP Link Controller
BIG-IP AAM
BIG-IP SSLO
BIG-IP DDHD
BIG-IP
SIMATIC TIM 1531 IRC
BIG-IP Advanced WAF
SINEC INS
Web Terminal
JBoss Core Services
Cloud Pak for Security (CP4S)
Gentoo Linux
ClevOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
macOS
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
Slackware Linux
Junos OS
Ubuntu
openEuler
Junos OS Evolved
Fedora
curl (Alpine package)
jbcs-httpd24 (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-jansson (Red Hat package)
curl (Red Hat package)
curl (Debian package)
jbcs-httpd24-curl (Red Hat package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-brotli (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
curl (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl3 (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl4 (Ubuntu package)
curl
curl-debuginfo
curl-debugsource
libcurl4-32bit
libcurl4
libcurl4-debuginfo-32bit
libcurl4-debuginfo
libcurl-devel
libcurl
curl-help
TensorFlow
Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
OpenShift Virtualization
Red Hat OpenShift Jaeger
Splunk Universal Forwarder
Splunk Enterprise
PeopleSoft Enterprise PeopleTools
Oracle Communications Billing and Revenue Management
GitLab Enterprise Edition
Gitlab Community Edition
BIG-IP PEM
BIG-IP FPS
BIG-IP LTM
BIG-IP AFM
BIG-IP Analytics
BIG-IP ASM
BIG-IP APM
BIG-IP GTM
BIG-IP DNS
BIG-IP Link Controller
BIG-IP AAM
BIG-IP SSLO
BIG-IP DDHD
BIG-IP
SIMATIC TIM 1531 IRC
BIG-IP Advanced WAF
SINEC INS
Web Terminal
JBoss Core Services
How to mitigate CVE-2020-8286
Install updates from vendor's website.
cURL - update to 7.74.0
TensorFlow - update to 2.5.0
Red Hat OpenShift Serverless - update to 1.16.0
jbcs-httpd24 (Red Hat package) - addressed in versions 1-18.el8jbcs, 1-18.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-82.el8jbcs, 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-105.el8jbcs, 1.6.3-105.jbcs.el7
Cloud Pak for Security (CP4S) - update to 1.8.0.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-17.el8jbcs, 1.15.7-17.jbcs.el7
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
Windows Container Support for Red Hat OpenShift - update to 2.0.1
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-36.el8jbcs, 2.0.8-36.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-74.el8jbcs, 2.4.37-74.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-63.GA.el8jbcs, 2.9.2-63.GA.jbcs.el7
jbcs-httpd24-jansson (Red Hat package) - addressed in versions 2.11-55.el8jbcs, 2.11-55.jbcs.el7
curl (Alpine package) - update to 7.74.0-r0
curl (Red Hat package) - update to 7.61.1-18.el8
curl (Debian package) - update to 7.64.0-4+deb10u2
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.77.0-2.el8jbcs, 7.77.0-2.jbcs.el7
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
macOS - addressed in versions 10.14.6 18G9028, 10.15.7 19H1030, 11.3 20E232
GitLab Enterprise Edition - addressed in versions 13.5.6, 13.6.4, 13.7.2
Gitlab Community Edition - addressed in versions 13.5.6, 13.6.4, 13.7.2
Junos OS - addressed in versions 15.1R7-S9, 17.3R3-S12, 17.4R3-S5, 18.1R3-S13, 18.3R3-S5, 18.4R2-S9, 18.4R3-S9, 19.1R3-S5, 19.2R3-S2, 19.3R2-S6, 19.3R3-S2, 19.4R1-S4, 19.4R2-S4, 19.4R3-S3, 20.1R2-S2, 20.1R3, 20.2R2-S3, 20.2R3, 20.3R2, 20.4R1-S1, 20.4R2, 21.1R1, 23.4R1-S1, 23.4R2, 24.1R1
Junos OS Evolved - addressed in versions 20.4R2-EVO, 21.1R1-EVO, 21.4R3-S4-EVO, 22.1R3-S4-EVO, 22.3R3-S1-EVO, 22.4R2-S1-EVO, 23.2R1-EVO
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-20.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - update to 1.0.0-5.el8jbcs
SINEC INS - update to 1.0.1.1
jbcs-httpd24-brotli (Red Hat package) - update to 1.0.6-40.el8jbcs
Web Terminal - update to 1.3
jbcs-httpd24-nghttp2 (Red Hat package) - update to 1.39.2-37.el8jbcs
SIMATIC TIM 1531 IRC - update to 2.2
JBoss Core Services - update to 2.4.37 SP8
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
curl (Ubuntu package) - addressed in versions 7.47.0-1ubuntu2.18, 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu4.2
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.47.0-1ubuntu2.18, 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu4.2
libcurl3 (Ubuntu package) - update to 7.47.0-1ubuntu2.18
libcurl3-nss (Ubuntu package) - addressed in versions 7.47.0-1ubuntu2.18, 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu4.2
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu4.2
curl - update to 7.60.0-4.20.1
curl-debuginfo - update to 7.60.0-4.20.1
curl-debugsource - update to 7.60.0-4.20.1
libcurl4-32bit - update to 7.60.0-4.20.1
libcurl4 - update to 7.60.0-4.20.1
libcurl4-debuginfo-32bit - update to 7.60.0-4.20.1
libcurl4-debuginfo - update to 7.60.0-4.20.1
curl - addressed in versions 7.69.1-7.fc32, 7.71.1-8.fc33
curl-debugsource - update to 7.71.1-5
curl - update to 7.71.1-5
libcurl-devel - update to 7.71.1-5
libcurl - update to 7.71.1-5
curl-debuginfo - update to 7.71.1-5
curl-help - update to 7.71.1-5
TensorFlow - update to 2.5.0
Red Hat OpenShift Serverless - update to 1.16.0
jbcs-httpd24 (Red Hat package) - addressed in versions 1-18.el8jbcs, 1-18.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-82.el8jbcs, 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-105.el8jbcs, 1.6.3-105.jbcs.el7
Cloud Pak for Security (CP4S) - update to 1.8.0.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-17.el8jbcs, 1.15.7-17.jbcs.el7
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
Windows Container Support for Red Hat OpenShift - update to 2.0.1
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-36.el8jbcs, 2.0.8-36.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-74.el8jbcs, 2.4.37-74.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-63.GA.el8jbcs, 2.9.2-63.GA.jbcs.el7
jbcs-httpd24-jansson (Red Hat package) - addressed in versions 2.11-55.el8jbcs, 2.11-55.jbcs.el7
curl (Alpine package) - update to 7.74.0-r0
curl (Red Hat package) - update to 7.61.1-18.el8
curl (Debian package) - update to 7.64.0-4+deb10u2
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.77.0-2.el8jbcs, 7.77.0-2.jbcs.el7
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
macOS - addressed in versions 10.14.6 18G9028, 10.15.7 19H1030, 11.3 20E232
GitLab Enterprise Edition - addressed in versions 13.5.6, 13.6.4, 13.7.2
Gitlab Community Edition - addressed in versions 13.5.6, 13.6.4, 13.7.2
Junos OS - addressed in versions 15.1R7-S9, 17.3R3-S12, 17.4R3-S5, 18.1R3-S13, 18.3R3-S5, 18.4R2-S9, 18.4R3-S9, 19.1R3-S5, 19.2R3-S2, 19.3R2-S6, 19.3R3-S2, 19.4R1-S4, 19.4R2-S4, 19.4R3-S3, 20.1R2-S2, 20.1R3, 20.2R2-S3, 20.2R3, 20.3R2, 20.4R1-S1, 20.4R2, 21.1R1, 23.4R1-S1, 23.4R2, 24.1R1
Junos OS Evolved - addressed in versions 20.4R2-EVO, 21.1R1-EVO, 21.4R3-S4-EVO, 22.1R3-S4-EVO, 22.3R3-S1-EVO, 22.4R2-S1-EVO, 23.2R1-EVO
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-20.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - update to 1.0.0-5.el8jbcs
SINEC INS - update to 1.0.1.1
jbcs-httpd24-brotli (Red Hat package) - update to 1.0.6-40.el8jbcs
Web Terminal - update to 1.3
jbcs-httpd24-nghttp2 (Red Hat package) - update to 1.39.2-37.el8jbcs
SIMATIC TIM 1531 IRC - update to 2.2
JBoss Core Services - update to 2.4.37 SP8
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
curl (Ubuntu package) - addressed in versions 7.47.0-1ubuntu2.18, 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu4.2
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.47.0-1ubuntu2.18, 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu4.2
libcurl3 (Ubuntu package) - update to 7.47.0-1ubuntu2.18
libcurl3-nss (Ubuntu package) - addressed in versions 7.47.0-1ubuntu2.18, 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu4.2
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu4.2
curl - update to 7.60.0-4.20.1
curl-debuginfo - update to 7.60.0-4.20.1
curl-debugsource - update to 7.60.0-4.20.1
libcurl4-32bit - update to 7.60.0-4.20.1
libcurl4 - update to 7.60.0-4.20.1
libcurl4-debuginfo-32bit - update to 7.60.0-4.20.1
libcurl4-debuginfo - update to 7.60.0-4.20.1
curl - addressed in versions 7.69.1-7.fc32, 7.71.1-8.fc33
curl-debugsource - update to 7.71.1-5
curl - update to 7.71.1-5
libcurl-devel - update to 7.71.1-5
libcurl - update to 7.71.1-5
curl-debuginfo - update to 7.71.1-5
curl-help - update to 7.71.1-5
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Slackware Linux update for curl
- Improper Check for Certificate Revocation in curl (Alpine package)
- Gentoo update for cURL
- GitLab security update for bundler and curl
- Improper certificate revocation in curl implementation within Command Line Interface, EAV Monitors and iRules components in F5 BIG-IP products
- Debian update for curl
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in macOS
- Tensorflow update for third-party components
- Red Hat Enterprise Linux 8 update for curl
- Multiple vulnerabilities in Siemens SIMATIC TIM 1531 IRC
- Red Hat update for JBoss Core Services Pack Apache Server
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in Windows Container Support for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in OpenShift Serverless
- Juniper Junos OS update for cURL
- Multiple vulnerabilities in Oracle Communications Billing and Revenue Management
- Multiple vulnerabilities in Red Hat Web Terminal
- Multiple vulnerabilities in Siemens SINEC INS
- SUSE update for curl
- Multiple vulnerabilities in IBM Cloud Pak for Security
- ClevOS update for IBM Cloud Object Storage Systems
- Splunk Universal Forwarder update for third-party packages
- Splunk Enterprise update for third-party packages
- openEuler update for curl
- Junos OS and Junos OS Evolved update for cURL
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in OpenShift Virtualization 2.6
- Ubuntu update for curl
- Fedora 33 update for curl
- Fedora 32 update for curl